Show filters
26 Total Results
Displaying 11-20 of 26
Sort by:
Attacker Value
Unknown

CVE-2023-23721

Disclosure Date: March 20, 2023 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in David Gwyer Admin Log plugin <= 1.50 versions.
Attacker Value
Unknown

CVE-2017-20098

Disclosure Date: June 27, 2022 (last updated February 24, 2025)
A vulnerability was found in Admin Custom Login Plugin 2.4.5.2. It has been classified as problematic. Affected is an unknown function. The manipulation leads to basic cross site scripting (Persistent). It is possible to launch the attack remotely.
Attacker Value
Unknown

CVE-2021-44096

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action - update_user. This allows a remote attacker to compromise Application SQL database.
Attacker Value
Unknown

CVE-2022-1589

Disclosure Date: May 30, 2022 (last updated February 23, 2025)
The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its settings, which could allow unauthenticated users to change the settings. The attacked could also be performed via a CSRF vector
Attacker Value
Unknown

CVE-2021-24867

Disclosure Date: February 21, 2022 (last updated February 23, 2025)
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
Attacker Value
Unknown

CVE-2021-24784

Disclosure Date: December 13, 2021 (last updated February 23, 2025)
The WP Admin Logo Changer WordPress plugin through 1.0 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin update them via a CSRF attack.
Attacker Value
Unknown

CVE-2020-23051

Disclosure Date: October 22, 2021 (last updated February 23, 2025)
Phpgurukul User Registration & User Management System v2.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the firstname and lastname parameters of the registration form & loginsystem input fields.
Attacker Value
Unknown

CVE-2021-34628

Disclosure Date: July 26, 2021 (last updated February 23, 2025)
The Admin Custom Login WordPress plugin is vulnerable to Cross-Site Request Forgery due to the loginbgSave action found in the ~/includes/Login-form-setting/Login-form-background.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.2.7.
Attacker Value
Unknown

CVE-2020-35263

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution.
Attacker Value
Unknown

CVE-2020-29228

Disclosure Date: December 30, 2020 (last updated February 22, 2025)
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Page.